VulnerabilityModified
CVE-2015-8329
SAP Manufacturing Integration and Intelligence (aka MII, formerly xMII) uses weak encryption (Base64 and DES), which allows attackers to conduct downgrade attacks and decrypt passwords via unspecified vectors, aka SAP Security Note 2240274.
MEDIUM 5.0EPSS 0.97%
Does this matter?
Lower severity and a low EPSS score (0.97%). Track it; it rarely justifies an emergency change on its own.
Description
SAP Manufacturing Integration and Intelligence (aka MII, formerly xMII) uses weak encryption (Base64 and DES), which allows attackers to conduct downgrade attacks and decrypt passwords via unspecified vectors, aka SAP Security Note 2240274.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 0.97% probability · 60th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-310
- Affected
- sap/manufacturing integration and intelligence
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/135761/SAP-MII-12.2-14.0-15.0-Cryptography-Issues.htmlThird Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2016/Feb/68
- https://erpscan.io/advisories/erpscan-15-031-using-base64-and-des-in-sap-mii/
- http://packetstormsecurity.com/files/135761/SAP-MII-12.2-14.0-15.0-Cryptography-Issues.htmlThird Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2016/Feb/68
- https://erpscan.io/advisories/erpscan-15-031-using-base64-and-des-in-sap-mii/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.